Cash App alerts 8 million customers to data breach

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

Mobile payments service Cash App has suffered a data breach after an ex-employee accessed sensitive customer data.

The company behind the service, Block (formerly Square), reported the incident to the US Securities and Exchange Commission (SEC) earlier this week.

In the filing, the company explained that the person was allowed to access this data as part of their past job responsibilities, but that access should have been barred the moment they left. Block has so far declined to explain why the employee was still able to access the data.

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

Personally identifiable information

The motive behind the exfiltration is unclear, but we know the person took customers' full names and brokerage account numbers, and in some cases, brokerage portfolio value, brokerage portfolio holdings, and stock trading data.

Usernames, passwords and other identity-related information were not accessed, it was said.

Block also refrained from revealing the number of customers affected, but did say it was reaching out to more than eight million current and former customers about the breach. All of them reside in the United States.

“At Cash App we value customer trust and are committed to the security of customers’ information,” a spokesperson told TechCrunch.

“Upon discovery, we took steps to remediate this issue and launched an investigation with the help of a leading forensics firm. We know how these reports were accessed, and we have notified law enforcement. In addition, we continue to review and strengthen administrative and technical safeguards to protect information.”

Earlier this week, cybersecurity experts from Imperva published a new report that suggested the majority of companies fail to take insider threat as seriously as they should.

Based on a survey of 500 security professionals, the report revealed that companies are often guilty of underestimating the extent of the threat posed by insiders, a conclusion perhaps reinforced by the Cash App breach.

According to Imperva, businesses need to add insider risk to their overall data protection strategy, and set up a diverse insider threat detection system that combines several tools.

Via TechCrunch

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Avast cybersecurity
Zapier tells customers their data may have been accessed
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
Major breach hits employee screening firm - 3.3 million affected as hackers steal DISA data
A computer being guarded by cybersecurity.
Zacks Investment hit in data breach - 12 million users potentially at risk
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
This widely-used instant loan app leaks nearly 30 million files of user data
Spyware
Stalkerware data breach potentially hits over 2 million users, including thousands of Apple devices
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)